codecperformersetup.exe

Installer

YellowSoft Inc

This is the Performersoft setup installer. The application codecperformersetup.exe by YellowSoft Inc has been detected as adware by 38 anti-malware scanners. The program is a setup application that uses the InstallBrain installer. According to AVG, this software downloads additional adware offers during setup. While running, it connects to the Internet address www.ibbalance.com on port 443.
Publisher:
YellowSoft Inc  (signed and verified)

Product:
Installer

Version:
15.9.28.27

MD5:
3e2aaf39d070a11d6436c95f0446aa30

SHA-1:
442af9ef8b55bb39539c91e4019c9ec0a59cebc9

SHA-256:
ff5988a4f371e35fd99d410ef1ce8bb02536e828348df6ed1b6887de80ade126

Scanner detections:
38 / 68

Status:
Adware

Explanation:
Uses the InstallBrain monetization platform from iBario to deliver bundled adware both search toolbars and PC optimizers from Performersoft.

Description:
This is an installer which may bundle legitimate applications with offers for additional 3rd-party applications that may be unwanted by the user. While the installer contains an 'opt-out' feature this is not set be defult and is usually overlooked.

Analysis date:
4/16/2024 3:53:03 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Application.Bundler.InstallBrain.A
354

Agnitum Outpost
Adware.BrainInst
7.1.1

AhnLab V3 Security
Adware/Win32.BrainInst
16.02.15

Avira AntiVirus
APPL/InstallBrain.Gen
7.11.144.152

avast!
Win32:Installer-AB [PUP]
2014.9-160215

AVG
Trojan horse Downloader.Generic13
2017.0.2832

Bitdefender
Application.Bundler.InstallBrain.A
1.0.20.230

Bkav FE
W32.HfsAdware
1.3.0.6379

Clam AntiVirus
Win.Trojan.Installbrain-270
0.98/20157

Comodo Security
TrojWare.Win32.Brantall.A
18140

Dr.Web
Adware.Downware.1522
9.0.1.046

Emsisoft Anti-Malware
Gen:Variant.Adware.Graftor.131298
8.16.02.15.05

ESET NOD32
Win32/InstallBrain.AV (variant)
10.9702

Fortinet FortiGate
Adware/BrainInst
2/15/2016

F-Prot
W32/IBrain.B2.gen
v6.4.7.1.166

F-Secure
Application.Bundler.InstallBrain
11.2016-15-02_2

G Data
Application.Bundler.InstallBrain
16.2.24

IKARUS anti.virus
not-a-virus:Downloader.Win32.Agent
t3scan.1.6.1.0

K7 AntiVirus
Trojan-Downloader
13.176.11524

Kaspersky
Trojan-Downloader.Win32.BrainInst
14.0.0.656

Malwarebytes
Adware.InstallBrain
v2016.02.15.05

McAfee
PUP-FDT!EEF04BF470C2
5600.6488

Microsoft Security Essentials
Threat.Undefined
1.173.2153.0

MicroWorld eScan
Application.Bundler.InstallBrain.A
17.0.0.138

NANO AntiVirus
Trojan.Win32.Downware.cqhnzm
0.28.0.59288

Norman
Application.Bundler.InstallBrain.A
11.20160215

nProtect
Trojan-Downloader/W32.BrainInst.875416
14.03.21.01

Panda Antivirus
PUP/Ibups
16.02.15.05

Qihoo 360 Security
Malware.QVM10.Gen
1.0.0.1015

Quick Heal
TrojanDownloader.Brantall.A5
2.16.12.00

Reason Heuristics
PUP.Performersoft.YellowSoft.Bundler (M)
16.2.15.17

Rising Antivirus
PE:Trojan.Brantall!6.100B
23.00.65.16213

Sophos
InstallBrain
4.98

SUPERAntiSpyware
PUP.InstallBrain/Variant
9322

Total Defense
Win32/Tnega.ICFFLHD
37.0.10889

Vba32 AntiVirus
TrojanDownloader.BrainInst
3.12.26.0

VIPRE Antivirus
InstallBrain
28448

Zillya! Antivirus
Downloader.BrainInst.Win32.7
2.0.0.1790

File size:
797.4 KB (816,536 bytes)

Product version:
15.9.28.27

Copyright:
Copyright 2012

Original file name:
installer.exe

File type:
Executable application (Win32 EXE)

Bundler/Installer:
InstallBrain

Language:
English (United States)

Common path:
C:\users\{user}\downloads\codecperformersetup.exe

Digital Signature
Signed by:

Authority:
GoDaddy.com, Inc.

Valid from:
9/12/2012 8:15:31 AM

Valid to:
9/12/2015 8:15:31 AM

Subject:
CN=YellowSoft Inc, O=YellowSoft Inc, L=Beaverton, S=OR, C=US

Issuer:
SERIALNUMBER=07969287, CN=Go Daddy Secure Certification Authority, OU=http://certificates.godaddy.com/repository, O="GoDaddy.com, Inc.", L=Scottsdale, S=Arizona, C=US

Serial number:
4EC8FFEF413CDC

File PE Metadata
Compilation timestamp:
10/10/2013 3:40:52 PM

OS version:
5.1

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
10.0

CTPH (ssdeep):
24576:Z8igGTlTL2xC98Xkm2NdClgU1mszk7Rd3Nj:RTlTL2E8XkmKdC91mYcL3F

Entry address:
0xC2BB

Entry point:
E8, AF, 4D, 00, 00, E9, 89, FE, FF, FF, 8B, FF, 55, 8B, EC, 53, 8B, 5D, 08, 83, FB, E0, 77, 6F, 56, 57, 83, 3D, 20, 67, 42, 00, 00, 75, 18, E8, FA, 45, 00, 00, 6A, 1E, E8, 44, 44, 00, 00, 68, FF, 00, 00, 00, E8, 3D, 31, 00, 00, 59, 59, 85, DB, 74, 04, 8B, C3, EB, 03, 33, C0, 40, 50, 6A, 00, FF, 35, 20, 67, 42, 00, FF, 15, 48, C0, 41, 00, 8B, F8, 85, FF, 75, 26, 6A, 0C, 5E, 39, 05, 24, 67, 42, 00, 74, 0D, 53, E8, 53, 2F, 00, 00, 59, 85, C0, 75, A9, EB, 07, E8, 1B, 1E, 00, 00, 89, 30, E8, 14, 1E, 00, 00, 89...
 
[+]

Entropy:
7.7977  (probably packed)

Code size:
105 KB (107,520 bytes)

The executing file has been seen to make the following network communications in live environments.

TCP (HTTP):
Connects to www.softologic.com  (174.37.181.31:80)

TCP (HTTP SSL):
Connects to www.ibbalance.com  (173.192.190.227:443)

Remove codecperformersetup.exe - Powered by Reason Core Security